2012 CVE Vulnerabilities

5,939 CVEs published in 2012.

CVE IDSeverityCVSSDescription
CVE-2012-6341MEDIUM6.5An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a mali...
CVE-2012-6340MEDIUM4.6An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial program...
CVE-2012-6309HIGH7.5A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malici...
CVE-2012-6307HIGH8.8A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious...
CVE-2012-6306CRITICAL9.8A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file.
CVE-2012-6297HIGH8.8Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containin...
CVE-2012-2593MEDIUM6.1Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote atta...
CVE-2012-5686CRITICAL9.8ZPanel 10.0.1 has insufficient entropy for its password reset process.
CVE-2012-5618CRITICAL9.8Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
CVE-2012-6133MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary ...
CVE-2012-5776MEDIUM5.4Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php.
CVE-2012-4383HIGH8.8contao prior to 2.11.4 has a sql injection vulnerability
CVE-2012-6610HIGH8.8Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitra...
CVE-2012-6609HIGH7.5Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J...
CVE-2012-6114MEDIUM5.5The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1...
CVE-2012-6448MEDIUM6.1Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web scrip...
CVE-2012-1496HIGH8.8Local file inclusion in WebCalendar before 1.2.5.
CVE-2012-1495CRITICAL9.8install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user...
CVE-2012-6613HIGH7.2D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admi...
CVE-2012-6494MEDIUM6.1Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's...
CVE-2012-6345HIGH7.5Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.
CVE-2012-6344MEDIUM6.1Novell ZENworks Configuration Management before 11.2.4 allows XSS.
CVE-2012-6451CRITICAL9.8Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
CVE-2012-6302HIGH7.8Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.
CVE-2012-6663HIGH7.5General Electric D20ME devices are not properly configured and reveal plaintext passwords.

Check if your code is affected by 2012 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now